Appearance
Platform Overview
OrviQ organizes enterprise GRC into 12 interconnected domains, providing a seamless flow from obligation scoping to risk mitigation and executive reporting.
The 12 Functional Domains
1. Home (/dashboard)
The central executive dashboard providing high-level visibility into compliance posture, open action items, upcoming deadlines, and assurance coverage across all business units.
2. Regulatory Compliance (/requirements, /scope-registry, /frameworks)
The catalog of all active regulatory frameworks, standards, and legal mandates. Define applicability rules in the Scope Registry, track individual obligations, and record formal compliance determinations.
3. Controls & Assurance (/controls, /crosswalk, /evidence, /assurance)
The internal control catalog. Manage internal controls, link them to regulatory obligations in the Control Crosswalk, maintain verified proof in the Evidence Fabric, and monitor continuous assurance indicators.
4. Risk Management (/risks, /findings, /action-plans, /exceptions, /rcsa)
Comprehensive risk management: track enterprise risks, log compliance findings, assign remediation action plans, conduct RCSA campaigns, and govern time-bound risk exceptions.
5. Policy Governance (/governance, /governance/library, /governance/expiry)
The centralized corporate policy repository. Manage policy authoring, version lifecycles, review cadences, policy-to-control links, and standard gap analyses.
6. Audit & Inspection (/audit, /inspections)
Manage internal and external audit engagements, store auditor workpapers, and coordinate regulatory supervisory inquiries and responses.
7. Third-Party Risk (/third-party-risk)
Vendor catalog and supplier risk management. Tier third-party vendors, record security assessments, and track contractual compliance obligations.
8. Operational Resilience (/bcm)
Business Continuity Management (BCM) and operational resilience. Conduct Business Impact Analyses (BIA), maintain continuity plans, and track simulation exercises.
9. Incidents & Loss Events (/incidents)
Record operational and cyber incidents, categorize root causes, track remediation tasks, and quantify financial or operational loss events.
10. Work & Decisions (/my-work, /approvals, /calendar)
Personalized execution hub. View assigned tasks in My Work, approve or reject submissions in the Approvals Hub, and track governance deadlines in the GRC Calendar.
11. Reports (/reports, /compliance-dashboard, /visualizer)
Comprehensive reporting tools, interactive compliance visualizers, and export facilities for stakeholders and regulatory bodies.
12. Administration (/settings, /admin/users, /settings/workflow, /settings/sla)
Tenant configuration, user management, Role-Based Access Control (RBAC), AI Provider setup, SLA thresholds, and maker-checker approval rules.
Inter-Domain Connectivity
OrviQ's strength lies in how these domains connect:
- A Regulatory Requirement connects to one or more Internal Controls via a Crosswalk Mapping.
- A Control is supported by Evidence Items and linked to Policies.
- If a Control fails or lacks evidence, a Finding is opened and an Action Plan is assigned.
- If remediation cannot be completed immediately, a Governed Exception is requested and approved.
- All human tasks flow automatically into My Work and the Approvals Hub.